cve-2026-60414
HIGH CVSS 7.8 opencveVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
- Published
- 2026-08-18 21:16 UTC
- Last Modified
- 2026-08-21
CVSS details not available.
No product information available.
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
mitre | ||
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
nvd | ||
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
opencve |
No references available.
{
"cve": "CVE-2026-60414",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "semver",
"value": "8.5.8"
}
}
],
"enrichment": {
"confidence": 89.0,
"confidence_source": "matching",
"scores": [
{
"score": 95.0,
"source": "inferred"
},
{
"score": 89.0,
"source": "matching"
}
]
},
"original": {
"product": "Oracle Outside In Technology",
"source": "cna",
"vendor": "Oracle Corporation"
},
"product": "outside_in_technology",
"vendor": "oracle"
}
],
"created": "2026-08-18T23:15:04.315201+00:00",
"title": "Unauthenticated Local Compromise of Oracle Outside In Technology",
"updated": "2026-08-21T21:00:03.296134+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$outside_in_technology"
]
},
"epss": {
"score": 0.00193
},
"mitre": {
"cpes": [
"cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*"
],
"created": "2026-08-18T20:58:54.969000+00:00",
"description": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/60xxx/CVE-2026-60414.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-20T15:00:06.706000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$outside_in_technology"
],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:16:38.013000+00:00",
"description": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-60414.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-21T14:50:04.373000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$outside_in_technology"
],
"weaknesses": [
"CWE-200"
]
},
"opencve": {
"changes": [
{
"created": "2026-08-18T21:15:00+00:00",
"data": [
{
"details": {
"new": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"old": null
},
"type": "description"
},
{
"details": [
"oracle",
"oracle$PRODUCT$outside_in_technology"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle",
"oracle$PRODUCT$outside_in_technology"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "dc0756c7-f077-4cec-b0eb-e2a18cfc36ef"
},
{
"created": "2026-08-18T23:30:00+00:00",
"data": [
{
"details": {
"new": "Unauthenticated Local Attack Compromise of Oracle Outside In Technology",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-284",
"CWE-862"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "118c5ff3-fe9c-4b03-a39e-c5b427eb4880"
},
{
"created": "2026-08-20T15:30:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-200"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "05562340-131f-4be1-8557-f1444f8109dc"
},
{
"created": "2026-08-20T16:30:00+00:00",
"data": [
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "3d64fa86-44bb-44bf-92d5-29b0400be9c0"
},
{
"created": "2026-08-21T17:00:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Unauthenticated Local Attack Compromise of Oracle Outside In Technology"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-284",
"CWE-862"
]
},
"type": "weaknesses"
}
],
"id": "459dab35-2fbd-4c5e-8665-0f5726af41fe"
},
{
"created": "2026-08-21T19:45:00+00:00",
"data": [
{
"details": {
"new": "Unauthenticated Local Compromise of Oracle Outside In Technology",
"old": null
},
"type": "title"
}
],
"id": "60ab2160-da8f-4a04-b4e8-3b627cf216ea"
}
],
"cpes": {
"data": [
"cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*"
],
"providers": [
"mitre",
"nvd"
]
},
"created": {
"data": "2026-08-18T20:58:54.969000+00:00",
"provider": "mitre"
},
"description": {
"data": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00193
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "Unauthenticated Local Compromise of Oracle Outside In Technology",
"provider": "enrichment"
},
"updated": {
"data": "2026-08-21T19:30:05.177248+00:00",
"provider": "enrichment"
},
"vendors": {
"data": [
"oracle",
"oracle$PRODUCT$outside_in_technology"
],
"providers": [
"mitre",
"nvd",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-200"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-08-18T20:58:54.969000+00:00",
"description": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [],
"title": null,
"updated": "2026-08-20T14:59:28.306000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/60xxx/CVE-2026-60414.json",
"weaknesses": [
"CWE-200"
]
}
}